Text Exploits

31,386 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-112433 EXPLOITDB text
Stock Management System 1.0 - 'brandId and categoriesId' SQL Injection
by Ihsan Sencan
EIP-2026-111924 EXPLOITDB text
School Faculty Scheduling System 1.0 - 'username' SQL Injection
by Jyotsna Adhana
EIP-2026-111923 EXPLOITDB text
School Faculty Scheduling System 1.0 - 'id' SQL Injection
by Jyotsna Adhana
EIP-2026-111391 EXPLOITDB text
Point of Sales 1.0 - 'username' SQL Injection
by Jyotsna Adhana
EIP-2026-111390 EXPLOITDB text
Point of Sales 1.0 - 'id' SQL Injection
by Ankita Pal
EIP-2026-109213 EXPLOITDB text
Lot Reservation Management System 1.0 - Cross-Site Scripting (Stored)
by Ankita Pal
EIP-2026-109212 EXPLOITDB text VERIFIED
Lot Reservation Management System 1.0 - Authentication Bypass
by Ankita Pal
EIP-2026-107539 EXPLOITDB text
Gym Management System 1.0 - Authentication Bypass
by Jyotsna Adhana
CVE-2020-27993 EXPLOITDB MEDIUM text
hrsale 2.0.0 - Path Traversal via Download Endpoint
Hrsale 2.0.0 allows download?type=files&filename=../ directory traversal to read arbitrary files.
by Sosecure
CVSS 5.3
EIP-2026-112435 EXPLOITDB text
Stock Management System 1.0 - 'Product Name' Persistent Cross-Site Scripting
by Adeeb Shah
EIP-2026-112434 EXPLOITDB text
Stock Management System 1.0 - 'Categories Name' Persistent Cross-Site Scripting
by Adeeb Shah
EIP-2026-112432 EXPLOITDB text
Stock Management System 1.0 - 'Brand Name' Persistent Cross-Site Scripting
by Adeeb Shah
EIP-2026-111926 EXPLOITDB text
School Faculty Scheduling System 1.0 - Stored Cross Site Scripting POC
by Jyotsna Adhana
EIP-2026-111925 EXPLOITDB text
School Faculty Scheduling System 1.0 - Authentication Bypass POC
by Jyotsna Adhana
EIP-2026-107445 EXPLOITDB text
GOautodial 4.0 - Authenticated Shell Upload
by Balzabu
CVE-2020-37227 EXPLOITDB HIGH text
WordPress Plugin HS Brand Logo Slider 2.1 Unrestricted File Upload
HS Brand Logo Slider 2.1 contains an unrestricted file upload vulnerability that allows authenticated users to bypass client-side file extension validation by uploading arbitrary files. Attackers can intercept upload requests to the logoupload parameter in the admin interface and rename files to executable extensions .php to achieve remote code execution.
by Net-Hunter
CVSS 8.8
CVE-2020-25905 EXPLOITDB CRITICAL text
Mobile Shop System 1.0 - SQL Injection via Email Parameter
An SQL Injection vulnerabilty exists in Sourcecodester Mobile Shop System in PHP MySQL 1.0 via the email parameter in (1) login.php or (2) LoginAsAdmin.php.
by Moaaz Taha
CVSS 9.8
CVE-2020-25760 EXPLOITDB HIGH text
Projectworlds Visitor Management System in PHP 1.0 - SQL Injection via 'rid' Parameter
Projectworlds Visitor Management System in PHP 1.0 allows SQL Injection. The file front.php does not perform input validation on the 'rid' parameter. An attacker can append SQL queries to the input to extract sensitive information from the database.
by Rahul Ramkumar
CVSS 8.8
EIP-2026-114209 EXPLOITDB text
Wordpress Plugin WP Courses < 2.0.29 - Broken Access Controls leading to Courses Content Disclosure
by redtimmysec
EIP-2026-112931 EXPLOITDB text
User Registration & Login and User Management System With admin panel 2.1 - Persistent XSS
by yusufmalikul
EIP-2026-109195 EXPLOITDB text
Loan Management System 1.0 - Multiple Cross Site Scripting (Stored)
by Akıner Kısa
EIP-2026-104496 EXPLOITDB text
WordPress Plugin Colorbox Lightbox v1.1.1 - Persistent Cross-Site Scripting (Authenticated)
by n1x_
CVE-2020-28141 EXPLOITDB MEDIUM text
Online Discussion Forum 1.0 - Authenticated Stored Cross-Site Scripting in Message Body
The messaging subsystem in the Online Discussion Forum 1.0 is vulnerable to XSS in the message body. An authenticated user can send messages to arbitrary users on the system that include javascript that will execute when viewing the messages page.
by j5oh
CVSS 5.4
CVE-2020-28136 EXPLOITDB HIGH text
Tourism Management System 1.0 - Unauthenticated Arbitrary File Upload via Admin Create Package
An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 1.0 allows the user to conduct remote code execution via admin/create-package.php vulnerable page.
by Ankita Pal
CVSS 8.8
CVE-2020-29458 EXPLOITDB HIGH text
Textpattern CMS 4.6.2 - Cross-Site Request Forgery via Prefs Subsystem
Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.
by Alperen Ergel
CVSS 8.8